Improper access control in Backdrop CMS - #VU105896
Published: March 20, 2025
Vulnerability identifier: #VU105896
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to a bug in the core Actions system. A remote attacker can use bulk actions to modify some values that they would not have permission to modify when editing individual nodes.
Affected software
Backdrop CMS
Remediation
Install updates from vendor's website.
Backdrop CMS - addressed in versions 1.29.4, 1.30.2